
Learn to install and manage Palo Alto firewalls using a sample topology, covering certificates, interface and zone setup, NAT and security policies, VPN, authentication, Panorama, and latest Pan-OS features.
Explore Palo Alto certifications: network security administrator and network security engineer. Learn formats and durations, including 50 questions in 90 minutes for administrator and 75 in 80 for engineer.
Configure the lab topology for Palo Alto training, linking Istanbul and Ankara via site-to-site VPN, with Istanbul firewall zones inside 172.16.0.0 and DMZ 10.1.0.0, and VLANs on ESXi and switches.
Prepare the virtual firewall installation by configuring VLAN groups on ESXi, setting trunk ports and sub-interfaces, and mapping management, WAN, and DMZ subnets to appropriate VLAN IDs.
Install a Palo Alto virtual firewall from an OVA, configure VLANs for management, WAN, inside, and DMZ ports, and set a static IP, gateway, and DNS. Commit and save configuration.
Learn to install a Palo Alto firewall in a Workstation Pro home lab, configuring management, WAN, inside, and DMZ interfaces across VM nets, and adjust Ethernet adapter types.
Activate the firewall license via the support panel, retrieve license keys from Palo Alto license servers, and review dashboard and management interface settings for proper licensing.
Create security zones to define boundaries: map the WAN interface to Outside zone, place the user subnet in the Inside zone, and place the server subnet in the DMZ zone.
Configure a virtual router and layer 3 interfaces on a Palo Alto firewall via the GUI, assigning Outside, Inside, and DMZ zones, then commit the changes.
Create interface management profiles to permit ping, http, https, ssh, and the response page, apply them to the appropriate interface, and test access to the firewall's graphical user interface.
Learn to create sub-interfaces on a Palo Alto firewall to terminate VLANs 11, 12, and 13, assign VLAN tags and IP addresses, and use a trunked switch.
Configure a DHCP server on the Palo Alto firewall to assign IPs for VLANs 11 and 12, create pools, set gateway and DNS, and verify with ipconfig.
Configure dhcp relay on the Palo Alto firewall to forward dhcp discovery from vlan 13 to an external dhcp server via interface 1/4.13.
Configure static routes in the network tab and virtual router 1, creating a default route 0.0.0.0/0 via the WAN interface and next hop 44.34.0.254 for internet access.
Introduce security policies by creating an inter-zone LAN-to-WAN rule for the inside 172.16.0.0 subnet, allowing http, https, and dns, with NAT configured in the next lesson.
Configure dynamic NAT (PAT) on a Palo Alto firewall to translate private addresses to a public IP, creating a lan-to-wan NAT rule and testing internet access while reviewing logs.
Configure static nat to let the web server in DMZ access the internet using 44.34.0.100. Create a web-server-static-nat rule translating 10.1.0.100 to 44.34.0.100 and allow http, https, dns.
Create a destination NAT rule under the policy tab to translate the web server's external 44.34.0.100 to the internal 10.1.0.100, enabling external access and logs.
Create application control and application filtering rules in a Palo Alto firewall, including a Facebook video block and a browser-based file sharing filter, with top-priority precedence.
Learn how to enable https inspection through ssl decryption on a Palo Alto firewall, create a certificate, configure decryption policies, and test with browser while excluding finance traffic.
Create and color tags in the object tab to label zones—green for inside, yellow for DMZ, and red for outside. Verify them in the policy tab for quick visual guidance.
Learn to create and apply an antivirus profile with threat prevention licensing, configure dynamic updates and SSL decryption to protect traffic, and verify malware blocks on https and http.
Learn to create an anti spyware profile in the Palo Alto firewall, using a Threat Prevention license, and configure key logger, peer-to-peer, backdoor, spyware, worm, and botnet rules.
activate vulnerability protection on Palo Alto firewall by verifying license and updates, create a test vulnerability profile with client and server rules for dos and sql, and apply.
Learn to activate the license, create a url filtering profile, and block categories such as high risk, adult, malware, and fishing using blacklist and whitelist on a Palo Alto firewall.
Create a file blocking profile under the security profile (object tab), block exe files in upload and download directions, apply it to the Lan-to-Wan rule, and test the block.
Enable the data filtering profile to block files containing credit card information by creating a data pattern, applying it to a lan-to-wan rule, and verifying blocked traffic and logs.
Create a WildFire analysis profile and apply it to the Lan-to-Wan rule, using a cloud-based virtual sandboxed environment to analyze unknown and targeted threats and alert administrators.
Create a DoS protection profile and a DoS protection policy on firewall, enabling SYN flood, UDP flood, ICMP flood, and ICMPv6 protections, then apply changes to block outside to inside.
Create and apply a zone protection profile to the outside zone to defend against DoS by enabling packet base attacks and icmp blocks larger than 1024.
Integrate active directory users by creating LDAP and authentication profiles on firewall, linking an LDAP server at 172.16.0.110:389, and using sAMAccountName for group-based access with HR, IT, and Sales groups.
Enable user-id on Palo Alto firewalls by configuring LDAP server, server monitor, and group mapping to enforce domain user policies. Test with domain-joined clients and review logs for user-based blocks.
Enable the authentication portal, select the created profile, and create an authentication portal policy for http/https access. Test with IT User-1 and verify portal appears in logs with LDAP.
Generate a csr on the firewall, request a certificate from the certificate authority, import the root certificate, install the pending certificate, and deploy the pa-ssl-vpn certificate, then commit the settings.
Create a layer 3 vpn zone named vpn-users and a tunnel interface, enable user identification, and use the ssl vpn certificate to support remote access; commit.
Configure Global Protect gateway and portal settings for SSL VPN, including gateway creation, authentication profiles, client settings, IP pool, split tunnel, DNS, and certificate configuration, then commit to the firewall.
Download and activate the Global Protect client, then create SSL traffic rules for external users using intra-zone and inter-zone configurations, and test connectivity to 44.34.0.1.
Configure IPsec site-to-site VPN between istanbul and ankara by creating a zone, tunnel interface, IKE and IPsec crypto profiles, gateway, tunnel, static routes, and security policies.
Explore role-based administration on Palo Alto firewalls by creating users, assigning profiles like monitor, and enforcing read-only or restricted access to policy, security, nat, and qos.
Learn to update PAN-OS on the Palo Alto firewall: verify license, back up with a named configuration snapshot, and upgrade from 8 to 9, then to 10, then to 10.0.3.
Master high availability on Palo Alto firewalls by configuring active/passive failover, using high availability ports and vlan 40/50 on esxi, and synchronizing policies and antivirus updates between devices.
Explore how Panorama centralizes firewall management, register firewalls, configure high availability, and push rules and policies across devices from a single Panorama interface.
Back up the device with a named configuration snapshot and export it. Perform a factory reset and restore from the backup by importing the previously saved file.
!!! YOU CAN GET DISCOUNT CODES FOR ALL MY TRAININGS FROM MY WEBSITE !!!
In this course, you can learn how to install and manage Palo Alto Firewall with step-by-step lab applications on sample topology.
Palo Alto Networks is one of the leading companies in the field of Network and Cyber Security today, by taking this course, you can prepare for the PCNSA - Palo Alto Networks Certified Network Security Administrator and PCNSE - Palo Alto Networks Certified Network Security Engineer exams, this course will help you a lot in preparation for the exams. .
By taking this course, you will be able to easily install and manage Palo Alto Next Generation Firewalls. In order for you to practice in this course, you can also explain the installation of Virtual Firewall on VmWare Workstation. You can download the VmWare Ova file required for this installation from the resources section under the relevant course.
What you will learn in the training, Palo Alto Firewall installation, basic settings, interface settings, routing settings, DHCP server settings, creating security policies and rules, protection from malware, protection against security vulnerabilities, prevention of DoS attacks, File blocking and Data Filtering, NAT settings, You will learn many topics such as Palo Alto Global Protect, Authentication Portal, Captive Portal, Site to Site VPN configuration and Device management.
I tried to convey this training to you in the best way with my 23 years of experience in the sector. I had a lot of fun while preparing the training, I have no doubt that you will enjoy watching it too.